PT-2023-28880 · Croc · Croc

Matthias Gerstner

·

Published

2023-09-19

·

Updated

2024-09-25

·

CVE-2023-43619

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Croc versions through 9.6.5
Description An issue was discovered in Croc where a sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized keys file.
Recommendations For Croc versions through 9.6.5, update to version 9.6.16 or later to resolve the issue. As a temporary workaround, consider restricting the types of files that can be sent through Croc to minimize the risk of exploitation. Avoid using Croc to transfer executable content or sensitive files like .ssh/authorized keys until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-43619
GHSA-PPJH-XP5V-46WC
GO-2023-2073

Affected Products

Croc